Lead Auditor-System Audit

Reserve Bank Information Technology

Navi Mumbai

On-site

INR 3,000,000 - 6,000,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Reserve Bank Information Technology (ReBIT) invites applications for a senior IT Audit professional with 9–12 years in PMO audits, information security and IS audits. The role spans Banking tech domains, policy writing and risk assessment across cyber security.

You will lead cloud and application security reviews (AWS/Microsoft hybrid), governance audits of IT projects, data-driven assurance using Python/SQL, and ensure compliance with RBI frameworks and ITGC controls.

Qualifications

  • Experience 9–12 years in PMO audits and information security reviews.
  • Exposure to Banking/Finance domains preferable.
  • Experience writing policies, procedures, and processes.
  • Conduct risk assessments covering Cyber Security domains.
  • Audits of AWS/Microsoft hybrid environments (IAM, S3, VPC, GuardDuty).
  • Deep-dive audits of Java-based applications focusing on API security and DevSecOps pipelines.

Responsibilities

  • Lead deep-dive audits of AWS/Microsoft hybrid environments.
  • Audit Java-based application security, focusing on API security, containerization (Docker/K8s), and DevSecOps pipelines.
  • Conduct performance audits of high-value IT projects, ensuring PMP/Agile milestones while maintaining security.
  • Develop data-driven dashboards using Python or SQL to track real-time risk.
  • Audit database security and management (Oracle, MS SQL) and related activity monitoring.
  • Ensure IT operations comply with RBI Cyber Security Framework and Global Internal Audit Standards (2024).
  • Review IT General Controls: IAM, network security, server, application, change management, backup and DR.
  • Possibly travel within Mumbai and across India for RBI-required audits.

Skills

Project management
Information security
Information System Audits
Cloud security
Database security
Network security
SOC
ITGC
Policy writing
Risk assessment
PMP/Agile
API security
DevSecOps
Python
SQL
Docker
Kubernetes
AWS
Azure

Tools

Python
SQL
Docker
Kubernetes
AWS
Azure

Job description

  • 9 to 12 years of total experience (upto 12 yrs.) in the field of Project Management review/audits, information security operations, Information System Audits encompassing experience into any of the Banking Technologies Domains Cloud Security, Database management and administration, Network security and SOC in addition to IT General controls (ITGC).
  • Exposure to the Banking / Finance / Payment industry domains would be preferrable.
  • Hands 1-on experience in the following areas:
  • Writing policies, procedures, and processes
  • Conducting risk assessment covering Cyber Security domains as noted below:
Hybrid Cloud Mastry:
  • Lead deep-dive audits of AWS (IAM, S3, VPC, GuardDuty) and Microsoft Hybrid environments.
Code & Architecture Review:
  • Audit Java-based application security, focusing on API security, containerization (Docker/K8s), and DevSecOps pipelines.
Project Governance:
  • Conduct performance audits of high-value IT projects, ensuring they meet PMP/Agile milestones without compromising on security.
Data-Driven Assurance:
  • Use Python or SQL to build automated "Continuous Auditing" dashboards that track risk in real-time.
Database Security:
  • Database administration and management - Oracle, MS SQL etc., Database Activity Monitoring tools, data security and localization.
Regulatory Alignment:
  • Ensure all IT operations comply with the latest RBI Cyber Security Framework and Global Internal Audit Standards (2024)
IT General Controls:
  • Familiarity with Technical Security controls of Identity & Access Management, Network, Server, Application, Change management, Backup and Restoration etc. and process controls reviews.
  • Understand BCP and DR processes and architecture.
  • Experience in conducting reviews based on ISO standards and regulatory guidelines in banking sector for a medium to large sized organization would be preferred.
  • Experience in conducting Information System Audits/Review
  • Must have experience in preparing quality deliverables such as audit reports, presentations, etc.
  • Excellent written, oral communication and presentation skills
  • Excellent organizational and interpersonal skills
  • Ability to work independently or as part of a team

Information technology / Banking and Financial services / Auditing / Cyber Security consulting

  • To evaluate the systemic impact of risks across Project Management (PMO) and ITIL service delivery.
  • Heavy-hitter who can dissect complex AWS/Azure/Hybrid-Cloud architectures and scrutinize the Java-based microservices.
  • Candidates may have to travel within Mumbai and across the country (if required) to perform audits, as per RBI requirements.
  • Conducting audit of Information security policies, procedures, and processes to identify process/design gaps.
  • Conduct audits of information security systems and infrastructure to verify systems are secure and support the related applications/business processes.
  • Conducts audits in different banking technology domains such as Active Directory, WAF, Network access security, End-point security, Application VA/PT/AppSec, SDLC, Database management and security, PCI-DSS, and IT General Controls etc.
  • Additional weightage will be given to candidates with experience in domains such as Cloud Security, API security, CI-CD pipeline, project management Audits, etc.
  • Developing project plans, work programs, evaluating system controls, identify risks and audit gaps, documenting results in proper audit report format, making recommendations, and communicating information to stakeholders.
  • Support in maintaining audit checklist and documents, trend analysis, preparing presentations etc.
  • Should be a self-learner and must keep updated with the latest security guidelines issued by regulators, international standards for information security, threats and vulnerabilities researched/discovered.
  • Research public domain to keep up to date knowledge on latest banking applications / technologies and emerging technologies – Cloud, Virtualisation, AI-ML, IOT, CI-CD, API security, etc. and ensure continuous learning in identified security competencies and new/emerging technologies.
  • All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Auditor-Immediate Joiner
Senior Auditor-Immediate Joiner

Reserve Bank Information Technology • Navi Mumbai

Hybrid
INR 1,500,000 - 2,000,000
Associate Auditor-Cybersecurity-Immediate joiner
Associate Auditor-Cybersecurity-Immediate joiner

Reserve Bank Information Technology • Navi Mumbai

On-site
INR 800,000 - 1,400,000
Assistant Manager - Cyber Security - IT-GRC
Assistant Manager - Cyber Security - IT-GRC

BDO India • Bengaluru Urban

On-site
INR 1,200,000 - 1,800,000
GM - IT Audit
GM - IT Audit

Paytm • Dadri

On-site
INR 1,800,000 - 2,800,000
IT Audit Lead
IT Audit Lead

Paytm Payment Gateway • Dadri

On-site
INR 1,200,000 - 1,800,000
Lead Auditor, Information Systems Audit
Lead Auditor, Information Systems Audit

T D Newton & Associates • Bengaluru

On-site
INR 1,200,000 - 1,500,000
GM - IT Audit
GM - IT Audit

One97 Communications Limited • Dadri

On-site
INR 1,800,000 - 2,400,000
IT Audit
IT Audit

Riskpro India Ventures • India

On-site
INR 600,000 - 1,200,000
Cyber Audit, Officer.
Cyber Audit, Officer.

State Street • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Inclusive development opportunities
Flexible work-life support
Paid volunteer days
Senior Internal IT Auditor - INTL India
Senior Internal IT Auditor - INTL India

Insight Global • Bengaluru

On-site
INR 1,800,000 - 3,200,000